AMT Sustainability · 全面可持续数字化
Data Privacy

Data Privacy

AMT structures its data-processing practices around China’s Data Security Law, PIPL and cross-border transfer rules, with mapping to key GDPR requirements, DPA templates and support for data-subject rights.

Key facts
China laws
DSL / PIPL / cross-border rules
Intl mapping
GDPR (DPO / DPA / rights)
Rights
All 7 data-subject rights
Deletion
30 / 90 / 180 days post-termination

China data-law compliance

AMT’s data-processing activities are designed around China’s three pillar data-protection laws.

Data Security Law

Data classification, important-data identification and lifecycle security management.

PIPL

Lawful processing bases, informed consent and separate consent for sensitive data.

Cross-border assessment rules

Transfer-route selection, standard-contract filing and PIPIA.

GDPR alignment

For customers with cross-border operations, AMT maps its privacy controls to key GDPR concepts for legal and procurement review.

  • Six lawful bases

    Consent / contract / legal obligation / vital interests / public interest / legitimate interests.

  • Data Processing Agreement

    A standard DPA template setting out controller / processor duties and sub-processor terms.

  • Data Protection Officer

    A data-protection contact is reachable at privacy@amt.com.cn.

  • Data-subject rights

    Supports access, rectification, erasure, restriction, portability and objection (GDPR Arts. 15–22).

AMT privacy practices

  • Data minimisation

    We collect only what the service requires, avoiding over-collection.

  • Purpose limitation

    Data is used only for agreed purposes; new purposes require fresh consent.

  • Encryption

    Encryption at rest and in transit, with extra protection for sensitive fields.

  • Access control + audit logs

    Least-privilege access with auditable logging of key actions.

  • Deletion options

    After termination, customers can choose a 30 / 90 / 180-day deletion window.

  • Portability & export

    Structured-format export to support migration and backup.

Supporting data-subject rights

AMT supports the following seven data-subject rights and helps customers, as controllers, respond to their end users.

Right to be informed

Clear notice of how data is collected and used.

Right of access

Access to how personal data is processed.

Rectification

Correct inaccurate personal data.

Erasure

Request deletion where applicable.

Restriction

Request a pause on certain processing.

Portability

Obtain or move data in a structured format.

Objection

Object to legitimate-interest processing.

Data Processing Agreement (DPA)

Customers can request a standard DPA template that sets out each party’s role and obligations.

AMT offers a standard DPA template aligned with both PIPL and GDPR frameworks, covering processing scope, purpose, duration, categories of data subjects, security measures (including ISO 27001 controls), sub-processor management, breach notification, deletion and return of data, and audit rights.

  • Request the latest DPA template via the sales or legal workflow.
  • See the Sub-processors page for the current list.